Microsoft Security, Compliance, and Identity Fundamentals (SC-900) practice questions
310 free questions with answers and explanations.
- 101.A financial institution needs to ensure that all sensitive data, whether stored on servers or transmitted across networks, is unreadable to unauthorized parties if intercepted. Which security principle is being addressed by this requirement?Describe the concepts of security, compliance, and identity
- 102.A company is concerned about employees using weak or compromised passwords. They want to implement a solution within Microsoft Entra ID that automatically detects and prevents the use of common, easily guessable passwords, even if the password meets complexity requirements. Which Microsoft Entra capability should they configure?Describe the capabilities of Microsoft Entra
- 103.A company is implementing a Zero Trust security model. They need a capability that ensures every access request, whether from inside or outside the network, is explicitly verified based on all available data points, including user identity, location, device health, and resource sensitivity. Which Zero Trust principle is being described, and which Microsoft Entra capability is central to its implementation?Describe the capabilities of Microsoft Entra
- 104.A small business is setting up its first cloud environment. They want to implement a security principle that minimizes the permissions granted to users and processes, ensuring they only have access to resources absolutely necessary to perform their function. Which security concept are they trying to implement?Describe the concepts of security, compliance, and identity
- 105.A company requires that employees accessing highly sensitive financial data must not only provide their username and password but also use a mobile authenticator app to generate a one-time code. This policy applies regardless of the employee's location or device. Which security measure is being enforced?Describe the concepts of security, compliance, and identity
- 106.A global enterprise needs to manage access to thousands of applications, both cloud-based and on-premises, and wants to centralize the management of user assignments and permissions for these applications. Which Microsoft Entra core capability provides this centralized management?Describe the capabilities of Microsoft Entra
- 107.A regulatory body has mandated that a healthcare organization must be able to demonstrate that all changes to patient medical records are traceable to the specific individual who made them, along with the timestamp of the change. Which security principle is being emphasized by this mandate?Describe the concepts of security, compliance, and identity
- 108.A security operations center (SOC) analyst observes a significant increase in sign-ins from unusual locations and impossible travel scenarios within Microsoft Entra ID. They need a capability that can detect these suspicious activities automatically and apply real-time remediation actions, such as blocking the sign-in or forcing a password change. Which Microsoft Entra capability provides this advanced threat detection and automated response?Describe the capabilities of Microsoft Entra
- 109.A security administrator needs to ensure that users are automatically prevented from signing in if their account shows signs of compromise, such as impossible travel or sign-ins from known malicious IP addresses. Which Microsoft Entra capability provides this automated protection?Describe the capabilities of Microsoft Entra
- 110.A small business is setting up its Microsoft Entra ID tenant. They want to allow employees to use their existing Microsoft 365 credentials to access various cloud applications without re-entering their username and password for each application. Which core Microsoft Entra capability enables this functionality?Describe the capabilities of Microsoft Entra
- 111.A healthcare provider is implementing a new patient management system. They need to ensure that patient records are only accessible to medical staff directly involved in the patient's care, and that access is automatically revoked when a staff member leaves their role or the organization. Which identity concept best supports these requirements?Describe the concepts of security, compliance, and identity
- 112.A global enterprise needs to manage access to its critical applications. They want to centralize identity management and allow users to access cloud-based and on-premises applications using a single set of credentials. Which core Microsoft Entra capability directly supports this requirement?Describe the capabilities of Microsoft Entra
- 113.A company wants to streamline the process of onboarding new employees and granting them access to necessary resources based on their department and job function. They also need to ensure that access is automatically removed when an employee leaves the company. Which Microsoft Entra governance capability would best address these requirements?Describe the capabilities of Microsoft Entra
- 114.A small business uses Microsoft 365 and wants to allow employees to use their existing Microsoft Entra ID credentials to access a third-party HR application. Which core Microsoft Entra capability enables this single sign-on (SSO) functionality?Describe the capabilities of Microsoft Entra
- 115.A financial institution requires a solution to ensure that all administrative roles within Microsoft Entra ID and connected Azure resources are assigned on a just-in-time (JIT) basis and that their usage is audited. This is to minimize standing access permissions and adhere to strict compliance regulations. Which Microsoft Entra governance capability is best suited for this requirement?Describe the capabilities of Microsoft Entra
- 116.An organization wants to simplify the sign-in experience for its mobile workforce by allowing them to authenticate to Microsoft Entra ID using their smartphones without entering passwords. The solution must support strong, multi-factor authentication. Which method best achieves this?Describe the capabilities of Microsoft Entra
- 117.A global corporation needs to manage access to sensitive resources based on user roles, location, and device compliance. They want to ensure that only compliant devices from specific locations can access certain applications. Which Microsoft Entra capability is best suited for implementing these granular access controls?Describe the capabilities of Microsoft Entra
- 118.A software development team needs to ensure that only specific versions of libraries and approved open-source components are used in their applications to prevent known vulnerabilities from being introduced. Which security concept is this related to?Describe the concepts of security, compliance, and identity
- 119.A financial services company needs to ensure that all administrative actions performed by privileged users are subject to review and approval before execution, even for temporary assignments. Additionally, they require a comprehensive audit trail of all privileged activity. Which Microsoft Entra governance capability is best suited for this stringent requirement?Describe the capabilities of Microsoft Entra
- 120.A security administrator wants to implement a solution that proactively detects and remediates identity-based risks, such as leaked credentials, impossible travel, and anomalous sign-in activities, within Microsoft Entra ID. Which Microsoft Entra capability is designed for this purpose?Describe the capabilities of Microsoft Entra
- 121.A company wants to ensure that all administrative roles within Microsoft Entra ID are assigned just-in-time and with time limits. Which Microsoft Entra capability should they implement?Describe the capabilities of Microsoft Entra
- 122.A security architect is designing a system where access decisions are not based on implicit trust derived from network location or ownership, but instead require continuous verification of every access request. This approach mandates verifying the user, device, and resource every time, assuming breach at all times. Which security framework is being adopted?Describe the concepts of security, compliance, and identity
- 123.A security architect is designing an identity solution for a company that wants to eliminate passwords for enhanced security and a streamlined user experience. They specifically want users to be able to sign in to Microsoft Entra ID-connected applications using a physical security key that supports strong, phishing-resistant authentication. Which authentication method should the architect recommend?Describe the capabilities of Microsoft Entra
- 124.A small business uses several cloud applications, each requiring separate login credentials. Employees are finding this cumbersome and often forget passwords, leading to security risks. Which identity concept would best address these issues by simplifying access while maintaining security?Describe the concepts of security, compliance, and identity
- 125.A global enterprise is implementing a new security framework. They want to achieve a state where, even if an attacker manages to compromise a single component or system, the impact of that breach is contained and does not lead to a widespread compromise of their entire network. This approach emphasizes limiting the blast radius of any potential security incident. Which security concept does this strategy represent?Describe the concepts of security, compliance, and identity
- 126.An organization wants to simplify the sign-in experience for its mobile workforce by allowing them to authenticate to Microsoft Entra ID without passwords, using a secure, phishing-resistant method that leverages hardware-backed security. Which authentication method should they prioritize for implementation?Describe the capabilities of Microsoft Entra
- 127.A university has multiple disparate systems for student registration, library access, and course management. They want to implement a solution where students can use a single set of credentials (username and password) to access all these different systems without re-entering their credentials for each one. Which identity solution would best achieve this goal?Describe the concepts of security, compliance, and identity
- 128.A global enterprise needs to manage access for its 100,000 employees across various cloud services and on-premises applications. They want a centralized system that stores user identities and attributes, allowing these services to authenticate users against a single, authoritative source. Which identity service best fits this requirement?Describe the concepts of security, compliance, and identity
- 129.A global financial institution needs to implement a security solution that allows its employees to access various internal applications and cloud services using a single set of credentials. This solution must also simplify user management and improve the overall user experience. Which identity concept best fits these requirements?Describe the concepts of security, compliance, and identity
- 130.A company wants to manage the lifecycle of user access to groups, applications, and SharePoint Online sites. They need a system that allows business owners to define access packages for resources and delegate approvals, while also ensuring that access is automatically removed when no longer needed. Which Microsoft Entra capability should they implement?Describe the capabilities of Microsoft Entra
- 131.A financial institution requires strict control over administrative roles in Microsoft Entra ID. They want to ensure that users are granted elevated privileges only when absolutely necessary and for a limited time, with an audit trail of all activations. Which Microsoft Entra capability supports this 'just-in-time' and 'just-enough-access' principle for privileged roles?Describe the capabilities of Microsoft Entra
- 132.A global enterprise needs to manage access for its 100,000 employees across various cloud services and on-premises applications. They require a centralized system to store user attributes, groups, and device information, which can then be used by different applications for authentication and authorization. Which identity concept is most relevant here?Describe the concepts of security, compliance, and identity
- 133.A multinational corporation needs a way to secure its cloud resources by defining policies that evaluate a user's device health, location, and the sensitivity of the data being accessed in real-time before granting access. Which Azure Active Directory feature is designed to enforce such dynamic access decisions?Describe the concepts of security, compliance, and identity
- 134.A company requires that all employees accessing highly sensitive applications must use a device that is both compliant with corporate security policies (e.g., up-to-date antivirus, OS patches) AND located within an approved geographical region. If either condition is not met, access should be denied. Which Microsoft Entra capability integrates with device compliance and location data to enforce these granular access controls?Describe the capabilities of Microsoft Entra
- 135.A software development team is building a new application that will run on Azure Virtual Machines. The application needs to access secrets stored in Azure Key Vault and also write logs to Azure Storage. The team wants to avoid hardcoding credentials or managing service principal secrets in their application code. Which identity solution should they implement for their application to securely access these Azure resources?Describe the concepts of security, compliance, and identity
- 136.A small business is setting up its cloud environment and wants to ensure that data remains unreadable to unauthorized individuals, even if they gain access to the storage location. Which security concept directly addresses this requirement?Describe the concepts of security, compliance, and identity
- 137.A financial institution is implementing a new system for managing customer accounts. They need to ensure that even if an attacker gains access to the database containing sensitive customer information, the data itself remains unreadable and unusable without a specific key. Which security measure should they prioritize to achieve this goal?Describe the concepts of security, compliance, and identity
- 138.A security operations center (SOC) analyst observes a significant increase in sign-ins from unfamiliar locations and IP addresses, as well as attempts to access sensitive data from compromised credentials. The company wants a Microsoft Entra capability that can proactively detect these identity-based risks, investigate them, and automate remediation actions like blocking access or forcing password resets. Which Microsoft Entra capability provides this functionality?Describe the capabilities of Microsoft Entra
- 139.A startup is rapidly expanding and needs to provide secure access to its cloud applications for new employees. They want to ensure that each new employee has the correct access rights to required applications and groups as soon as their account is created, streamlining the onboarding process and reducing manual provisioning errors. Which Microsoft Entra capability should they leverage?Describe the capabilities of Microsoft Entra
- 140.A global organization is implementing a security strategy to protect its intellectual property. They want to ensure that access to highly sensitive design documents is granted only after verifying multiple attributes about the user, their device, and their location. Which security concept does this scenario primarily describe?Describe the concepts of security, compliance, and identity
- 141.A small startup is rapidly expanding and needs to provide secure access to its cloud applications for a growing number of external contractors and partners. They want to manage these external identities centrally within Microsoft Entra ID, allowing partners to use their own existing corporate or social identities for sign-in. Which Microsoft Entra capability supports this scenario?Describe the capabilities of Microsoft Entra
- 142.A global company has a strict compliance requirement to ensure that all users accessing corporate applications from unmanaged devices are always prompted for multi-factor authentication (MFA) and have their session restricted to prevent data download. Additionally, users accessing from managed devices within the corporate network should have a seamless sign-on experience without MFA. Which Microsoft Entra capability can provide this level of granular control?Describe the capabilities of Microsoft Entra
- 143.A company requires that all users, including guests, periodically confirm their continued need for access to sensitive applications and groups. This process is essential for compliance and to reduce the risk of stale access permissions. Which Microsoft Entra governance capability is designed to automate and manage this periodic review of access?Describe the capabilities of Microsoft Entra
- 144.A compliance officer is reviewing the organization's data handling policies to ensure adherence to a new privacy regulation. The regulation mandates that customer data must be deleted upon request within a specific timeframe and that its retention period is strictly limited. Which compliance concept is most directly addressed by these requirements?Describe the concepts of security, compliance, and identity
- 145.A company is implementing a new system for managing employee access to various internal applications. They want to categorize users into groups based on their job functions (e.g., 'HR Staff', 'Finance Team', 'IT Admins') and assign permissions to these groups rather than to individual users. This approach simplifies management and ensures consistency. Which identity concept is being applied?Describe the concepts of security, compliance, and identity
- 146.A healthcare organization is subject to strict regulations like HIPAA, which mandates the protection of electronic protected health information (ePHI). They need to ensure that their IT systems are configured to prevent unauthorized modification or destruction of patient records. Which security principle are they primarily focusing on?Describe the concepts of security, compliance, and identity
- 147.A software development team is building a new application that will store sensitive customer data. They need to implement a mechanism to prove the origin of the data and ensure that it has not been tampered with since its creation or last modification. Which security concept is most relevant here?Describe the concepts of security, compliance, and identity
- 148.A large enterprise needs a scalable solution to manage external contractors and partners who require temporary access to specific applications and data. The solution must allow these external users to use their existing corporate or social identities to sign in, rather than creating new accounts in the enterprise's Microsoft Entra ID. Which Microsoft Entra capability is best suited for this scenario?Describe the capabilities of Microsoft Entra
- 149.A small startup is handling customer data and wants to ensure that only authorized personnel can access this information. They are particularly concerned about preventing unauthorized disclosure. Which core security principle are they primarily focusing on?Describe the concepts of security, compliance, and identity
- 150.A security auditor observes that several users have been assigned highly privileged roles in Microsoft Entra ID, such as Global Administrator, on a permanent basis. The auditor recommends implementing a solution that provides just-in-time and just-enough access for these roles. Which Microsoft Entra capability addresses this recommendation?Describe the capabilities of Microsoft Entra